SQL Injection Vulnerability in SOGo Product by Alinto
CVE-2026-46446

7.1HIGH

Key Information:

Vendor

Alinto

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2026-46446?

In versions of SOGo prior to 5.12.7, a security vulnerability has been identified when using PostgreSQL or MariaDB. This issue arises when cleartext passwords are stored, enabling an attacker to execute SQL injection attacks via the 'changePasswordForLogin' functionality. Proper sanitization and handling of sensitive data are critical to preventing unauthorized access and exploitation of user credentials.

Affected Version(s)

SOGo 0 < 5.12.7

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.